Browse Source

Microblog virtual host

Bob Mottram 10 years ago
parent
commit
295032245c
1 changed files with 99 additions and 2 deletions
  1. 99
    2
      install-freedombone.sh

+ 99
- 2
install-freedombone.sh View File

@@ -2311,6 +2311,103 @@ quit" > $INSTALL_DIR/batch.sql
2311 2311
       fi
2312 2312
   fi
2313 2313
 
2314
+  echo 'server {' > /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2315
+  echo '    listen 80;' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2316
+  echo "    server_name $MICROBLOG_DOMAIN_NAME;" >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2317
+  echo "    root /var/www/$MICROBLOG_DOMAIN_NAME/htdocs;" >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2318
+  echo "    error_log /var/www/$MICROBLOG_DOMAIN_NAME/error.log;" >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2319
+  echo '    index index.php;' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2320
+  echo '' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2321
+  echo '    rewrite ^ https://$server_name$request_uri? permanent;' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2322
+  echo '}' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2323
+  echo '' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2324
+  echo 'server {' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2325
+  echo '    listen 443 ssl;' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2326
+  echo "    root /var/www/$MICROBLOG_DOMAIN_NAME/htdocs;" >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2327
+  echo "    server_name $MICROBLOG_DOMAIN_NAME;" >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2328
+  echo "    error_log /var/www/$MICROBLOG_DOMAIN_NAME/error_ssl.log;" >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2329
+  echo '    index index.php;' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2330
+  echo '    charset utf-8;' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2331
+  echo '    client_max_body_size 20m;' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2332
+  echo '    client_body_buffer_size 128k;' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2333
+  echo '' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2334
+  echo '    ssl on;' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2335
+  echo "    ssl_certificate /etc/ssl/certs/$MICROBLOG_DOMAIN_NAME.crt;" >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2336
+  echo "    ssl_certificate_key /etc/ssl/private/$MICROBLOG_DOMAIN_NAME.key;" >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2337
+  echo "    ssl_dhparam /etc/ssl/certs/$MICROBLOG_DOMAIN_NAME.dhparam;" >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2338
+  echo '' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2339
+  echo '    ssl_session_timeout 5m;' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2340
+  echo '    ssl_prefer_server_ciphers on;' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2341
+  echo '    ssl_session_cache  builtin:1000  shared:SSL:10m;' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2342
+  echo '    ssl_protocols TLSv1 TLSv1.1 TLSv1.2; # not possible to do exclusive' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2343
+  echo "    ssl_ciphers 'EDH+CAMELLIA:EDH+aRSA:EECDH+aRSA+AESGCM:EECDH+aRSA+SHA384:EECDH+aRSA+SHA256:EECDH:+CAMELLIA256:+AES256:+CAMELLIA128:+AES128:+SSLv3:!aNULL:!eNULL:!LOW:!3DES:!MD5:!EXP:!PSK:!DSS:!RC4:!SEED:!ECDSA:CAMELLIA256-SHA:AES256-SHA:CAMELLIA128-SHA:AES128-SHA';" >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2344
+  echo '    add_header X-Frame-Options DENY;' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2345
+  echo '    add_header X-Content-Type-Options nosniff;' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2346
+  echo '    add_header Strict-Transport-Security "max-age=15768000;";' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2347
+  echo '' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2348
+  echo '    # rewrite to front controller as default rule' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2349
+  echo '    location / {' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2350
+  echo '        rewrite ^/(.*) /index.php?q=$uri&$args last;' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2351
+  echo '    }' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2352
+  echo '' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2353
+  echo "    # make sure webfinger and other well known services aren't blocked" >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2354
+  echo '    # by denying dot files and rewrite request to the front controller' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2355
+  echo '    location ^~ /.well-known/ {' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2356
+  echo '        allow all;' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2357
+  echo '        rewrite ^/(.*) /index.php?q=$uri&$args last;' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2358
+  echo '    }' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2359
+  echo '' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2360
+  echo '    # statically serve these file types when possible' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2361
+  echo '    # otherwise fall back to front controller' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2362
+  echo '    # allow browser to cache them' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2363
+  echo '    # added .htm for advanced source code editor library' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2364
+  echo '    location ~* \.(jpg|jpeg|gif|png|ico|css|js|htm|html|ttf|woff|svg)$ {' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2365
+  echo '        expires 30d;' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2366
+  echo '        try_files $uri /index.php?q=$uri&$args;' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2367
+  echo '    }' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2368
+  echo '' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2369
+  echo '    # block these file types' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2370
+  echo '    location ~* \.(tpl|md|tgz|log|out)$ {' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2371
+  echo '        deny all;' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2372
+  echo '    }' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2373
+  echo '' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2374
+  echo '    # pass the PHP scripts to FastCGI server listening on 127.0.0.1:9000' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2375
+  echo '    # or a unix socket' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2376
+  echo '    location ~* \.php$ {' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2377
+  echo '        # Zero-day exploit defense.' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2378
+  echo '        # http://forum.nginx.org/read.php?2,88845,page=3' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2379
+  echo "        # Won't work properly (404 error) if the file is not stored on this" >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2380
+  echo "        # server, which is entirely possible with php-fpm/php-fcgi." >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2381
+  echo "        # Comment the 'try_files' line out if you set up php-fpm/php-fcgi on" >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2382
+  echo "        # another machine. And then cross your fingers that you won't get hacked." >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2383
+  echo '        try_files $uri $uri/ /index.php;' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2384
+  echo '        # NOTE: You should have "cgi.fix_pathinfo = 0;" in php.ini' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2385
+  echo '        fastcgi_split_path_info ^(.+\.php)(/.+)$;' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2386
+  echo '        # With php5-cgi alone:' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2387
+  echo '        # fastcgi_pass 127.0.0.1:9000;' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2388
+  echo '        # With php5-fpm:' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2389
+  echo '        fastcgi_pass unix:/var/run/php5-fpm.sock;' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2390
+  echo '        include fastcgi_params;' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2391
+  echo '        fastcgi_index index.php;' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2392
+  echo '        fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2393
+  echo '    }' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2394
+  echo '' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2395
+  echo '    # deny access to all dot files' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2396
+  echo '    location ~ /\. {' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2397
+  echo '        deny all;' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2398
+  echo '    }' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2399
+  echo '' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2400
+  echo '    location ~ /\.ht {' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2401
+  echo '      deny  all;' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2402
+  echo '    }' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2403
+  echo '}' >> /etc/nginx/sites-available/$MICROBLOG_DOMAIN_NAME
2404
+
2405
+  configure_php
2406
+
2407
+  nginx_ensite $MICROBLOG_DOMAIN_NAME
2408
+  service php5-fpm restart
2409
+  service nginx restart
2410
+
2314 2411
   # some post-install instructions for the user
2315 2412
   if ! grep -q "To set up your microblog" /home/$MY_USERNAME/README; then
2316 2413
       echo '' >> /home/$MY_USERNAME/README
@@ -2330,8 +2427,8 @@ quit" > $INSTALL_DIR/batch.sql
2330 2427
       echo ' - Site profile: Community' >> /home/$MY_USERNAME/README
2331 2428
       echo '' >> /home/$MY_USERNAME/README
2332 2429
       echo "Navigate to https://$MICROBLOG_DOMAIN_NAME and you can then " >> /home/$MY_USERNAME/README
2333
-	  echo 'complete the configuration via the *Admin* section on the header' >> /home/$MY_USERNAME/README
2334
-	  echo 'bar.  Some recommended admin settings are:' >> /home/$MY_USERNAME/README
2430
+      echo 'complete the configuration via the *Admin* section on the header' >> /home/$MY_USERNAME/README
2431
+      echo 'bar.  Some recommended admin settings are:' >> /home/$MY_USERNAME/README
2335 2432
       echo '' >> /home/$MY_USERNAME/README
2336 2433
       echo 'Under the *Site* settings:' >> /home/$MY_USERNAME/README
2337 2434
       echo '    Text limit: 140' >> /home/$MY_USERNAME/README